QID 317313
Date Published: 2023-03-27
QID 317313: Cisco Internetwork Operating System (IOS) XE Software Privilege Escalation Vulnerability (cisco-sa-iosxe-priv-esc-sABD8hcU)
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
An attacker could exploit this vulnerability by modifying the Meraki registration parameters. A successful exploit could allow the attacker to elevate privileges to root.
Solution
Customers are advised to refer to cisco-sa-iosxe-priv-esc-sABD8hcU for more information.
Vendor References
- cisco-sa-iosxe-priv-esc-sABD8hcU -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-priv-esc-sABD8hcU
CVEs related to QID 317313
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-iosxe-priv-esc-sABD8hcU |
|